An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.
CVSS Details
- CVSS 4.0 Base Score: 5.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mongodb80 | May 8, 2026 | May 7, 2026 |
| Mongodb | — | Upgrade MongoDB to version 8.0.21Upgrade MongoDB to version 7.0.32Upgrade to the latest version of MongoDBUpgrade MongoDB to version 8.2.7 | May 7, 2026 | Apr 29, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.2.5Upgrade Splunk Enterprise to version 10.4.1Upgrade Splunk Enterprise to version 9.4.13Upgrade Splunk Enterprise to version 10.0.8 | Jul 30, 2026 | Apr 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub